Ledger Connect Kit compromised after phishing attack on a former employee
- Organization
- Ledger
- Exploit
- Phishing
- Industry
- Cryptocurrency Hardware
Ledger, the Paris-based cryptocurrency hardware wallet maker, was compromised on December 14, 2023 through its software supply chain. According to Ledger's own incident report, a former employee was targeted by a phishing attack, and the attacker then circumvented two-factor authentication on that person's NPM account by exploiting an API key associated with it. Ledger said access to NPM had not been properly revoked when the employee left.
With that access the attacker published three tampered releases of Ledger Connect Kit, versions 1.1.5, 1.1.6 and 1.1.7. The library is embedded in the front ends of numerous decentralized applications, so users connecting a wallet through an affected site could be served a script that redirected assets to the attacker's wallet. Ledger said the malicious code went live at 09:49 CET, that ecosystem partners alerted the company at 13:45, and that a clean version was deployed by 14:18, within 40 minutes of the alert. About five hours passed between the initial compromise and full resolution, with the window for actual theft under two hours.
Estimates of the losses differ. TechCrunch, citing the researcher known as ZachXBT, reported more than $600,000 drained, while The Cyber Express put the figure at $484,000. Ledger said it reported the attacker's wallet address, which became visible on Chainalysis, and that Tether froze the attacker's USDT, then tightened third-party access controls, code review and deployment policies afterwards.
Sources
- Ledger, Security Incident Report
- TechCrunch, Supply chain attack targeting Ledger crypto wallet leaves users hacked
- The Cyber Express, Ledger Cyberattack: Company Confirms Deactivation of Malicious Code in Ledger Connect Kit
- Ledger, A letter from Ledger Chairman and CEO Pascal Gauthier regarding the Ledger Connect Kit exploit